Redhat
Redhat Enterprise Linux Server AUS: vulnerabilidades y CVE
Redhat Enterprise Linux Server AUS tiene 1059 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 190 son críticas y 37 figuran en el catálogo de explotación activa de CISA.
CVE1059
Últimos 12 meses3
Críticas190
Explotadas activamente37
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0492 | Alta (7.8) | 5.5% | ⚠ Explotación activa | 3 mar 2022 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to… |
| CVE-2018-14634 | Alta (7.8) | 15% | ⚠ Explotación activa | 25 sept 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on… |
| CVE-2013-0648 | Alta (8.8) | 11% | ⚠ Explotación activa | 27 feb 2013 | Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before… |
| CVE-2013-0643 | Alta (8.8) | 11% | ⚠ Explotación activa | 27 feb 2013 | The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges,… |
| CVE-2014-0497 | Crítica (9.8) | 100% | ⚠ Explotación activa | 5 feb 2014 | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via… |
| CVE-2014-0502 | Alta (8.8) | 25% | ⚠ Explotación activa | 21 feb 2014 | Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR… |
| CVE-2023-4911 | Alta (7.8) | 81% | ⚠ Explotación activa | 3 oct 2023 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES… |
| CVE-2016-9079 | Alta (7.5) | 87% | ⚠ Explotación activa | 11 jun 2018 | A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects… |
| CVE-2016-3427 | Crítica (9.8) | 92% | ⚠ Explotación activa | 21 abr 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2014-3153 | Alta (7.8) | 37% | ⚠ Explotación activa | 7 jun 2014 | The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE… |
| CVE-2015-4495 | Alta (8.8) | 69% | ⚠ Explotación activa | 8 ago 2015 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via… |
| CVE-2017-8291 | Alta (7.8) | 97% | ⚠ Explotación activa | 27 abr 2017 | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs… |
| CVE-2019-8720 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 6 mar 2023 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption… |
| CVE-2014-0160 | Alta (7.5) | 100% | ⚠ Explotación activa | 7 abr 2014 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted… |
| CVE-2022-0847 | Alta (7.8) | 93% | ⚠ Explotación activa | 10 mar 2022 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale… |
| CVE-2012-2034 | Alta (7.5) | 7.8% | ⚠ Explotación activa | 9 jun 2012 | Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on… |
| CVE-2013-1690 | Alta (8.8) | 69% | ⚠ Explotación activa | 26 jun 2013 | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which… |
| CVE-2013-2729 | Crítica (9.8) | 67% | ⚠ Explotación activa | 16 may 2013 | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727. |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-5201 | Alta (7.5) | 1.2% | — | 31 mar 2026 | A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG… |
| CVE-2026-4424 | Alta (7.5) | 1.1% | — | 19 mar 2026 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression… |
| CVE-2025-13601 | Alta (7.7) | 0.32% | — | 26 nov 2025 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable… |
| CVE-2025-6021 | Alta (7.5) | 1.4% | — | 12 jun 2025 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when… |
| CVE-2025-3155 | Alta (7.4) | 14% | — | 3 abr 2025 | A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an… |
| CVE-2025-2784 | Media (6.5) | 0.84% | — | 3 abr 2025 | A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a… |
| CVE-2025-1756 | Alta (7.8) | 0.16% | — | 27 feb 2025 | mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\.… |
| CVE-2024-12088 | Alta (7.5) | 4.7% | — | 14 ene 2025 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a… |
| CVE-2024-12087 | Alta (7.5) | 2.3% | — | 14 ene 2025 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly… |
| CVE-2024-12085 | Alta (7.5) | 8.8% | — | 14 ene 2025 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized… |
| CVE-2024-9676 | Media (6.5) | 1.3% | — | 15 oct 2024 | A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill… |
| CVE-2024-9675 | Media (4.4) | 0.39% | — | 9 oct 2024 | A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary… |
| CVE-2024-7006 | Alta (7.5) | 1.5% | — | 12 ago 2024 | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or… |
| CVE-2024-6387 | Alta (8.1) | 100% | — | 1 jul 2024 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able… |
| CVE-2023-3758 | Alta (7.1) | 1.0% | — | 18 abr 2024 | A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. |
| CVE-2022-24809 | Media (6.5) | 1.1% | — | 16 abr 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a… |
| CVE-2022-24808 | Media (6.5) | 1.1% | — | 16 abr 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to… |
| CVE-2022-24807 | Media (6.5) | 1.0% | — | 16 abr 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds… |
| CVE-2022-24806 | Media (5.3) | 1.1% | — | 16 abr 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed… |
| CVE-2022-24805 | Alta (8.8) | 1.3% | — | 16 abr 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory… |
| CVE-2024-1488 | Alta (7.3) | 0.32% | — | 15 feb 2024 | A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port… |
| CVE-2024-1062 | Media (5.5) | 0.31% | — | 12 feb 2024 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. |
| CVE-2023-6536 | Alta (7.5) | 1.5% | — | 7 feb 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer… |
| CVE-2023-6535 | Alta (7.5) | 1.5% | — | 7 feb 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer… |
| CVE-2023-6356 | Alta (7.5) | 1.5% | — | 7 feb 2024 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer… |
| CVE-2023-5992 | Media (5.9) | 1.2% | — | 31 ene 2024 | A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. |
| CVE-2023-5455 | Media (6.5) | 0.57% | — | 10 ene 2024 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as… |
| CVE-2024-0193 | Media (6.7) | 0.84% | — | 2 ene 2024 | A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a… |
| CVE-2023-5870 | Media (4.4) | 2.6% | — | 10 dic 2023 | A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation… |
| CVE-2023-5869 | Alta (8.8) | 4.3% | — | 10 dic 2023 | A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230Openstack · 210